← All posts / Tools

Not-a-Mused: Patrick Wardle's Muse for Mac Zero-Day Turns Meta's Personal Agent Into a Cross-Device Backdoor

Objective-See founder Patrick Wardle disclosed a local zero-day in Meta's Muse for Mac: any unprivileged process can flip an undocumented setting to hijack dictated prompts, steal the account token, and invisibly task linked iPhones — location lookups and Bluetooth scans included.

Not-a-Mused: Patrick Wardle's Muse for Mac Zero-Day Turns Meta's Personal Agent Into a Cross-Device Backdoor

Meta shipped the Mac client for Muse, its cross-device personal AI agent, on September 17. Four days later, one of the most respected names in macOS security published proof-of-concept code showing how to turn that client into a ready-made backdoor — one whose reach extends past the compromised Mac to every other device signed into the same Muse account, including iPhones.

Patrick Wardle, founder of the Objective-See Foundation, a former NASA and NSA analyst, and author of The Art of Mac Malware, posted a three-part demonstration on September 21 under an unmistakable headline: “Please don’t install. It’s trivial to turn Muse into the ultimate backdoor.”

He calls the flaw not-a-mused. The technical core is small. The implications for how the industry secures personal agents are not.

The setting that shouldn’t have been settable

At the heart of the exploit is an undocumented Muse configuration option named endo_voyager_dictation_endpoint. According to Wardle’s repository, any local process running as the user — with no elevated privileges, no root, and no special entitlements — can modify this setting and redirect Muse’s dictation traffic to an attacker-controlled server.

The trigger for the victim is utterly mundane: click the microphone icon and dictate a prompt, exactly as the product is designed to be used. Once the endpoint is swapped, everything the user says flows to the attacker instead of Meta. Wardle’s write-up says the interception enables three distinct harms: captured dictated audio and prompts, prompt injection into the assistant, and theft of Muse’s authentication material — the token that proves the session to Meta’s backend.

The flaw is a local zero-day: it presumes an adversary who can already execute code under the user’s account. That prerequisite narrows the immediate threat — this is not a drive-by remote compromise of an untouched Mac. But Wardle’s argument is that Muse is a disproportionately valuable target precisely because of what it holds.

Access amplification, not exotic exploitation

To function as a personal agent, Muse requests sweeping permissions across the user’s digital life: files, microphone, camera, location, calendar, Messages, Notes and Mail, plus — through its connector system — the ability to browse, fill forms, send email and make purchases. Apple’s Transparency, Consent and Control (TCC) framework would normally stop ordinary malware from obtaining location access or microphone capture without explicit approval.

Wardle’s insight is that malware doesn’t need to defeat TCC when it can simply hijack an app the user already trusted with everything. “Muse’s access can potentially become the attacker’s access,” the exploit’s documentation states. He characterizes the bug as access amplification: compromise a client already carrying the user’s identity and permissions, and you inherit its entire reach without touching a single protected boundary.

Reaching through to the iPhone

The most striking part of the disclosure is the third post in Wardle’s thread. Using the stolen session, his code queries Muse’s account API for its device inventory — each connected device advertises a device identifier, its online status, and the commands it supports. Wardle says Muse exposes more than fifty such commands; his public proof of concept implements a subset.

His demonstration selected an online iPhone linked to the same account and directed Muse to invoke commands on it. On-screen results showed the phone returning its location — in Barcelona — and kicking off a Bluetooth Low Energy scan for nearby devices. Wardle says the mobile tasks ran invisibly through the Muse client. Categories of actions available through a compromised session reportedly include retrieving an iPhone’s location, scanning for nearby Bluetooth devices, and accessing information such as contacts, calendars and reminders. Messaging, by contrast, would only prepare a draft rather than send silently.

That is the structural lesson of the disclosure. Personal agents concentrate permissions across computers, phones and cloud accounts by design. Wardle’s exploit shows how a single local breach on one endpoint inherits that concentrated reach and crosses device boundaries — from a compromised Mac to a phone in another country, without the phone’s user seeing anything.

Meta’s boundary stops at the client

Meta has made security a headline feature of Muse, which launched on September 8 as “the world’s first personal AI agent built for everyone.” The architecture centers on Muse Secure VM, a dedicated cloud computer holding the agent’s data and connected credentials, with a separate Sentinel service described as the sole authority for connector actions and network egress. Meta’s technical security description says the agent never receives raw passwords or authentication tokens, and that mobile clients connect directly to the user’s VM over a secure transport layer.

None of that is contradicted by Wardle’s finding — because his attack targets a different boundary entirely: the software installed on the user’s own computer, and the trust linking that client to the wider account. Cloud isolation offers limited protection when a local client can be redirected before its traffic ever reaches the protected environment. Meta opened a Muse bug bounty at launch, paying up to $300,000 for qualifying reports, and its security documentation focused heavily on prompt injection, credential isolation and attacks against the cloud agent. The desktop client, it turns out, was the softer edge.

Wardle said he will share further details — and further bugs — at the Objective by the Sea security conference in November, which suggests this disclosure is the opening of a longer conversation rather than the end of one.

The pattern we should have learned by now

The industry has been here before. The viral open-source agent OpenClaw — known in its early days as Clawdbot — prompted warnings from companies and researchers throughout the year over exactly this risk: handing an AI agent broad access to a computer, files and accounts creates a single point of catastrophic failure. Muse is the polished, corporate version of that pattern, and it inherits the same endpoint-security problem in a shinier box. Malware does not need to defeat every layer of a defense-in-depth architecture when it can take over a trusted client that already carries the user’s identity.

For Muse users, the practical calculus is straightforward. The attack requires local code execution first, so standard Mac hygiene — no pirated software, no sketchy installers — remains the primary defense. But the blast radius once that foothold exists is no longer the compromised computer; it is every device and service the agent can touch. Until Meta ships a fix and documents why a dictation endpoint was client-configurable at all, Wardle’s advice is the conservative reading: don’t install it, or if you already have, understand what you’ve entrusted to it.

The deeper issue will outlast this bug. As agents gain connector ecosystems, cross-device command surfaces and purchasing power, “the client is trusted” becomes the most expensive assumption in the stack. Not-a-mused is a specific flaw in a specific app — but it is also a preview of the attack class that defines the agentic era.